Coldcard Wallet Exploit Pushes Losses to $114 Million Amid New Sweeps
Recent Coldcard Exploits Lead to Significant Losses
Recent reports indicate that losses associated with the Coldcard wallet have reached approximately $114 million. This figure is attributed to a series of attacks that have targeted addresses generated by the device, marking the emergence of a fourth sweep of exploitative transactions.
Details of the Exploits
From July 30, around 1,816 bitcoin has reportedly been moved from more than 5,200 compromised addresses. The latest of these attacks began early Monday and is indicative of a trend where an attacker employs a method known as replace-by-fee. This technique allows them to overwrite unconfirmed transactions by paying higher transaction fees.
Investigation and Response
Alex Thorn, head of firmwide research at Galaxy Research, highlighted the importance of noting these transactions since they provide victims with a narrow window to secure their funds by paying higher fees if they see their addresses listed in the mempool.
The attacks can be traced back to a flaw present in a March 2021 firmware version of the Coldcard wallet, which used a predictable software randomizer for seed generation rather than utilizing the device’s hardware randomization. As a result, this led to the generation of reproducible keys, making them vulnerable.
Manufacturer’s Response
In light of the situation, Coinkite, the manufacturer of Coldcard wallets, has issued emergency firmware updates for all affected models. They have advised users who generated wallets using the compromised firmware to transfer their funds to newly generated wallet addresses.
Current Status and User Recommendations
Thorn noted that while there have been no direct reports from victims as he based his findings on transaction patterns, the urgency remains for users to act quickly. He urged individuals to check their funds and move any assets off affected devices promptly. The sweeping patterns demonstrate a significant increase in attacks compared to prior controls, with a notable frequency of 14 sweeps per block versus a typical 0.3.
Source: coindesk.com